Symbolic execution for the XorShift128+ algorithm.
Go to file
TACIXAT 29ce8b02ca
Update README
2020-03-24 20:13:13 -07:00
README Update README 2020-03-24 20:13:13 -07:00
xs128p.py Fix Chrome. 2020-03-24 20:01:44 -07:00

README

For usage on the LA Time's powerball simulator. Careful about clicking the page.

Blog post: https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f

Run the following snippet in your browser's console.

    _ = []; for(var i=0; i<5; ++i) { _.push(Math.random()) } ; console.log(_)

Paste at least 3 of those (5 for Chrome) values into the dubs array in main().

It will warn you if the model is too "loose" and has multiple solutions.

Set the browser in main() to Chrome or Firefox. (Safari hasn't updated yet.)

    python xs128p.py

The winning numbers should have an arrow. Click once on the number inputs and tab between them to enter your "pick".

Click once on the play button.

Enjoy your lotto winnings :)



Hey, while you're here, I teach some security stuff on YouTube. https://cybering.cc

Follow me on Twitter! @cyberingcc